Raytha CMS User Enumeration Vulnerability in Password Reset Functionality
Vulnerability
A user enumeration vulnerability has been identified in Raytha CMS versions prior to 1.5.0, specifically within the password reset feature. The issue arises from discrepancies in response messages, which can inadvertently reveal the validity of login credentials. This flaw enables attackers to conduct brute force attacks using valid usernames or email addresses.
Impact
Exploitation of this vulnerability could lead to unauthorized account access by allowing attackers to reset passwords for valid users.
Remediation
Users can upgrade to Raytha CMS version 1.5.0 or later to address this vulnerability.
Added: Mar 16, 2026, 2:36 PM
Updated: Mar 16, 2026, 2:36 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
1.3exploitability
7.4remediation
0.0relevance
4.0threat
0.0urgency
2.9incentive
4.2Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
